CVE-2023-5519
EventPrime < 3.2.0 - Booking Creation via CSRF
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected products
Unknown · EventPrimeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →